Sears Home Services experienced a data exposure event after a security researcher found three unsecured databases connected to the company's AI-powered customer support systems. Cybersecurity researcher Jeremiah Fowler identified roughly 3.7 million records tied to the retailer's virtual assistant, which manages scheduling, phone calls, and online chats for the home services division.
The exposed data included nearly 1.4 million audio recordings of customer calls and more than 54,000 complete chat transcripts, some running from the start of a conversation to its end. Fowler noted that in cases where a caller failed to properly end a session, the AI system kept recording for up to four hours, capturing conversations unrelated to the original service request.
Records contained customer names, email addresses, phone numbers, physical addresses, and details about products, repairs, and delivery appointments dating back to 2024. Fowler warned that leaked chatbot logs can reveal how an AI assistant escalates issues, follows guardrails, and responds to specific prompts, information that could help bad actors manipulate the system or exploit it at scale.
A responsible disclosure notice was sent to Transformco, the parent company of Sears Home Services, and the exposed database was secured within a day. Fowler said his notice was forwarded to a staff member overseeing the chatbot but that he never received a direct response confirming what had happened or how long the data had been accessible.
It remains unclear how long the databases were publicly reachable before discovery or whether anyone besides the researcher accessed the information.
Source: Security Magazine - https://www.securitymagazine.com/articles/102188-37m-records-exposed-many-belonging-to-sears-home-services
